Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomeSecureSafe Pass Extension
Findings · 3
+1 more finding locked
LOW FINDINGS · 3
  1. 01Background WebRPC client transmits per-domain credential lookups (URL/hostname) to vendor host for autofill matching.
  2. 02AutofillIframeManager.sendMessage posts to the extension-controlled autofill iframe with targetOrigin '*' rather than the extension origin.
  3. 03document.addEventListener('clearPendingCredentials', ...) accepts CustomEvent.detail from any page and forwards it as a runtime message to background; bridge is callable by every site.
+1 more finding locked
OTHER EXTENSIONS

Is SecureSafe Pass Extension safe?

Low risk

No summary available.

DSwiss Ltd.v1.0.5Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.dswiss.securesafe.bro.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact